Skip to content

MinIO official Docker images are no longer published #418

@BlakeOrth

Description

@BlakeOrth

MinIO recently made the decision to make its public repository a "source only" distribution:

This means the MinIO official docker image will no longer be updated.

To add insult to injury, shortly after MinIO made the decision to stop publishing docker images, a high severity (8.1/10) CVE was disclosed and patched, meaning the official docker images are susceptible to the attack.
Privilege Escalation via Session Policy Bypass in Service Accounts and STS

While the CVE is probably not terribly impactful for a module that's intended for local testing, it is indicative of the types of issues that could continue to crop up if the MinIO image remains pointed to the official Docker repository.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions